cbcvebase.
CVE-2026-27683
published 2026-04-14

CVE-2026-27683: SAP BusinessObjects Business Intelligence application allows an authenticated attacker to inject malicious JavaScript payloads through crafted URLs. When a…

medium4.1CVSS 3.1
AVNACLPRLUIRSCCLINAN
SAP BusinessObjects Business Intelligence application allows an authenticated attacker to inject malicious JavaScript payloads through crafted URLs. When a victim accesses the URL, the script executes in the user�s browser, potentially exposing restricted information. This results in a low impact on confidentiality with no impact on integrity and availability.

Affected

3 ranges
VendorProductVersion rangeFixed in
sap_sesap_businessobjects_business_intelligence_platform
sap_sesap_businessobjects_business_intelligence_platform
sap_sesap_businessobjects_business_intelligence_platform